Soru

Zorluk: OrtaSecurity Governance Structures and Policy Frameworks

A governance team at an online retail company is reviewing its security documentation hierarchy to ensure operational compliance across all engineering units. Which of the following governance document types establish mandatory requirements that all employees and system configurations must follow? (Select TWO).

  1. High-level organizational security policiesCevap
  2. Specific technical baseline security standardsCevap
  3. C
    Recommended operational security guidelines
  4. D
    Discretionary implementation whitepapers
  5. E
    Informational vendor best practice documents

Cevap

The mandatory governance document types are high-level organizational security policies and specific technical baseline security standards.
High-level organizational security policies and specific technical baseline security standards represent compulsory components of a security framework. Policies set top-down management directives that require compliance across the entity, while standards define mandatory operational parameters and baseline controls. In contrast, guidelines, implementation whitepapers, and vendor best practices offer discretionary suggestions rather than enforceable obligations.

Adım Adım Çözüm

1
Analyze the governance documentation hierarchy to separate mandatory controls from discretionary guidance.
Policies and standards/baselines carry mandatory compliance requirements across the organization.
Executive policies establish overarching business expectations, while standards mandate technical configurations and measurable compliance targets.
2
Evaluate guidelines, whitepapers, and vendor best practices against mandatory enforcement criteria.
These document types provide non-binding recommendations and reference information.
Guidelines and whitepapers offer implementation flexibility and operational advice without imposing compulsory requirements.

Anahtar Kavram

Mandatory vs. Discretionary Governance Documents
Bu soruyu puanla